Privacy
This is a translation provided for your convenience. The Italian version is the legally binding one: read it here.
Who this page is for
This page explains how we handle the personal data connected to Muffin Staff. Not every reader is in the same position, and it's worth saying so straight away.
- If you are a client, or you are considering the software: read all of it. Here you'll find how we handle your data, and how the relationship between you and us works when it comes to your employees' data.
- If you work in a venue that uses Muffin Staff: the notice about your data has to come from your employer, because the data controller is your employer, not us. Further down there is a section for you, and a description of what the software records about you.
Who handles the data
Muffin Staff is a program by Muffin Suite, the name Antonio Fuccillo trades under, an Italian sole proprietorship.
- Antonio Fuccillo, Via Molini 26, 36055 Nove (VI), Italy
- P. IVA 04650850243
- Email info@muffin-suite.com, phone +39 352 012 5997
- Certified email (PEC) antonio.fuccillo@pec.it
- Support Monday to Friday, 9:00 to 18:00
Who publishes this site, with all the details art. 7 of Legislative Decree 70/2003 requires to be kept accessible, is set out in the legal notice. This notice covers both the site and the software. It's written the way art. 12 of the GDPR asks: so that it can be understood.
Two different roles, and they're worth keeping apart
We don't always have the same role over the same data. It depends which data we're talking about.
- We are the controller for the site data, for what you leave us when you write or call, and for the contract, the subscription and the invoices. Here we decide what to process and why, and we answer for it.
- We are the processor (art. 28 of the GDPR) for the data that ends up inside the software: your venue's staff, the shifts, the clock-ins, the absences. There you are the controller.
To be plain about it: you are the controller of your employees' data, because you are their employer. You decide who goes into the software, what information to enter, when to delete it. We keep the tool running and process that data only on your instructions, as art. 28(3)(a) of the GDPR provides: we don't use it for purposes of our own. Along with the contract you also sign a data processing agreement, the one art. 28 of the GDPR asks controller and processor to put in writing.
One thing this page does not do: it describes the roles, it doesn't divide up liability. That division is in the contract, in the terms and conditions of use and in the art. 28 agreement, within the limits art. 1229 of the Italian Civil Code sets for clauses that exclude liability. The duties the GDPR places on us as a processor, under arts. 28 and 32, stand regardless, as does our liability under art. 82(2) when we fail to meet them or act outside your instructions. No line on this page releases us from those duties.
We have no DPO
We have not appointed a data protection officer (DPO). We looked at the criteria in art. 37(1) of the GDPR, both as a controller and as a processor, and the appointment turns out not to be mandatory; we look at it again as the number of venues and of people managed grows. There is no mailbox in between: requests about data go straight to info@muffin-suite.com, and Antonio Fuccillo answers.
What Muffin Staff is, and what it involves
Muffin Staff is shift and attendance software for businesses that serve the public: restaurants, pizzerias, bars, ice cream shops, hotels, spas and other trades. It keeps the staff records, builds the shifts within holidays, days off and contract hours, records clock-ins with a QR code, marks absences and tips, and shows staff hours and costs.
All of that means handling the personal data of real people: those who work in the venue, and those who run it. There are three levels of access: Muffin Suite administrator, venue owner, employee. Each one sees what their role needs: an employee sees their own shifts, their own clock-ins and their own absences. In the shared plan they also see their colleagues' published shifts, because that's how you know who is on duty; the reason for someone else's absence, no, and you decide who in the venue can see it.
One thing has to be said plainly, because it's the point that matters most: to be able to support you, the Muffin Suite administrator can enter your business and see the data inside it. He does it when support or a technical fix calls for it, not for anything else, and his entry, like the operations he performs, stays written in the activity log. We won't tell you otherwise, because it wouldn't be true.
Venues stay separate from each other. Almost every table in the database carries the company identifier and every query filters on it: two venues can't see each other and nothing passes between them.
Two ways of running it, and they change everything
- In the cloud, on muffin-staff.it. The data sits on our server. Everything you read below applies.
- Installed on your company's PC. The software starts from your computer and writes to a database that stays on your computer. In this case your employees' data never passes through us: we hold no copy of it and we don't access it. There is one exception, though, and it's better written down than discovered: if you ask for support that requires looking at your data, that access happens only with your written authorization, case by case, limited to the job and for as long as it takes, and at that moment we handle the data as a processor, on your instructions. This case too falls under the art. 28 agreement you sign along with the contract. The computer the software runs on, and its backups, stay in your hands, not ours. For the rest, the parts of this notice that concern you are the ones about the site, the contract and the invoicing.
What data we collect
People who visit the site and people who write to us
If you just read the site, we ask you for nothing. There are no third-party analytics tools, and the fonts and the images are hosted on our own domain: while you browse no request goes out to anyone else's server. A request leaves only if you are the one who sends it, by opening the WhatsApp link.
The only thing the site saves on your device is the confirmation that you closed the notice at the bottom of the page. It isn't a cookie: it sits in the browser's local storage and stays there until you clear the site data. Your consent isn't needed, and the reason is a precise one: art. 122(1) of the Italian Privacy Code (Legislative Decree 196/2003) covers both cookies and local storage, and it doesn't require consent for what is strictly necessary to provide a service you asked for yourself. The details are on the cookies page.
There is a contact form on the site, at the bottom of the Muffin Staff page. What you write there — name, contact details and message — reaches our server and then our mailbox, and we keep it only to answer you. We don't use it to send you advertising and we don't give it to anyone.
You can also talk to us with your own tools, without going through the form: WhatsApp, the phone on 352 012 5997 or email to info@muffin-suite.com. In that case what you write arrives straight in our mailbox or on our phone, along with the contact details you wrote from.
If you write to us on WhatsApp on +39 352 012 5997, we read your message in order to answer you. WhatsApp has stayed on as a way of getting in touch, not as a feature of the software: Muffin Staff no longer sends the shifts over WhatsApp. What remains, on the Support page inside the software, is a button that opens WhatsApp with a message already written, carrying your name and the venue's name, if you press it. Until you press it, nothing goes anywhere. From that moment WhatsApp's own notice applies too, and WhatsApp is run by Meta Platforms Ireland.
The web server keeps the ordinary operating logs: IP address, date and time, page requested, outcome, referring page and browser type. An IP address is personal data, so we say so instead of calling all of it "technical data": it's there to keep the service running, to work out faults and to defend it from abuse. For how long we keep it, see the retention periods further down.
The client and their business
When you open a trial or start a subscription we handle, as controller:
- venue name, address, town, type of business
- VAT number, certified email (PEC)
- mobile and landline number
- notes about the business
- the agreed fee, the VAT rate applied, the billing period (monthly), due dates and the state of the subscription
- the details of the owner's account and of the Muffin Suite administrator's account: email, the encrypted fingerprint of the password, date and time of the last login
The fee is agreed per venue: to invoice you we ask for no extra data about your employees.
The people who work in the venue
Here you are the controller and we are the processor. For each person, the software can hold:
- Personal record: first name, last name, email, phone, tax code, date of birth
- Account status: role (owner or employee), record active or switched off, and whether the person goes into the shifts or is an owner who doesn't work the floor
- Login: the encrypted fingerprint of the password (nobody keeps the password in the clear, not even us), whether it must be changed on first entry, the counter that revokes sessions, date and time of the last login
- Contract and grade: main job and secondary jobs, type of contract (permanent, fixed-term, apprenticeship, on-call, seasonal, internship), collective agreement grade, CNEL collective agreement code, seniority increments granted, end of the probation period, weekly hours, hourly cost, hiring date, contract end date
- Holidays and leave: days and hours per year, opening balances
- Preferences and limits for building the shifts: whether overtime is allowed and the cap on overtime hours, the maximum number of consecutive days, of shifts per week and of hours per day, preferred day off, work on public holidays, preferred slot (lunch, dinner or either), assignment priority
- Free-text notes the owner writes about the person
- Clock-ins: the exact date and time, whether it was an entry or an exit, by which method (QR code or entered by hand), from which station, the IP address it came from, any notes and, if the owner corrected it, the original time and who corrected it
- Absences: holidays, leave, personal commitments, sickness and injury, with the dates and a free-text notes field the person asking for the absence can fill in
- Assigned shifts and declared availability, including shift swap requests between colleagues, with any reason written by whoever makes them
- Tips and the shares split between people
- Support tickets: the subject and the text of the messages you send us from inside the software, with the name of the person writing and the venue they belong to. Both owners and employees open them, and these we do read, because that's how we answer you: it's the only text written by your employees that comes under our eyes
- Activity log: who did what and when inside the software (creating and changing shifts, absences, staff records), so a mistake can be traced back
- Statistics worked out from this data, such as hours worked and staff cost
We collect no categories of data other than these.
On location, the exact wording is this: the software doesn't use GPS and doesn't ask the browser where you are. The clock-in QR code is a signed code that changes by itself every 30 seconds, it holds no personal data and no coordinates. It does record the IP address the clock-in came from, as any site does, and the name of the station you chose yourself. We collect no biometric data: no fingerprints, no face recognition.
One important thing to tell your employees: the notes about a person and the notes about an absence are free-text fields, and whatever gets written in them becomes personal data like the rest. They are for organizing the work, not for judgments or information that has nothing to do with it.
Sickness and injury are health data
When you record an absence for sickness or for injury, you are handling data about health. It's a special category of data, the one in art. 9 of the GDPR, and it calls for more care than the rest. We would rather say so plainly than hide it at the bottom of a list.
The software records the type of absence, the dates and a free-text notes field the person asking for the absence can fill in. There is no "diagnosis" field at all. No medical certificates or health attachments get uploaded: no part of the software accepts files.
From which comes a practical warning, for you and for your employees: that notes field is not to be used for the diagnosis or for clinical details. Knowing it's sickness or injury, and how long it lasts, is enough. It isn't only common sense: art. 5 of the Workers' Statute (Law 300/1970) forbids the employer from investigating illnesses and allows them to know the prognosis alone, that is the duration, not what it is about. That's why there is no diagnosis field in Muffin Staff, and why there must not be one.
The employer answers for this processing, which means you. The legal basis is art. 9(2)(b) of the GDPR: the processing is necessary to carry out obligations in the field of employment and social security law. It has to be read together with art. 88 of the GDPR, which leaves member states room for more precise rules on the employment relationship, and with art. 2-septies of the Italian Privacy Code (Legislative Decree 196/2003), which does not set the measures itself but leaves it to the Garante to adopt the safeguards for health data, and which in paragraph 8 forbids disclosing it in any case. In plain words: the employee's consent isn't needed, because you have to handle sickness by law, but for that very reason you can't use that data for anything else.
What we do to protect it:
- we keep it inside the same perimeter as the rest of the data, on the server in France; the backup stays on that same machine and isn't sent to any outside service
- we don't read it and we don't use it for ourselves: we go into it only if you ask us to for a support job, and only for as long as it takes
- it stays shut inside your venue: no other client can see it, because of the way the software separates companies
- the software doesn't send it to any outside service, because it doesn't call outside services
Clock-ins and monitoring: what Italian law requires
Attendance software touches a subject that in Italy has rules of its own, on top of the GDPR. They are worth setting out in full, instead of getting away with an "it isn't there to monitor anyone".
Muffin Staff is set up as a tool for recording entries and attendance. For tools of this kind, art. 4(2) of Law 300/1970 requires neither a union agreement nor authorization from the Labor Inspectorate. But the exemption covers the installation, not the use: for the data collected to be usable for every purpose connected with the employment relationship, disciplinary purposes included, art. 4(3) requires you to give workers a notice on how the tool is used and how the monitoring is carried out, and to comply with the Italian Privacy Code, which art. 114 of Legislative Decree 196/2003 brings into employment matters. Without that notice the data is still recorded, but you can't use it.
So what falls to you isn't only "giving the privacy notice":
- A privacy notice to employees (arts. 13 and 14 of the GDPR), which you have to give as the data controller. This page is no substitute for it.
- A notice on how the tool is used and how monitoring is done (art. 4(3) of Law 300/1970), without which clock-ins and statistics can't be used for disciplinary purposes.
- A notice on automated decision-making or monitoring systems (art. 1-bis of Legislative Decree 152/1997, introduced by Legislative Decree 104/2022 and amended by Decree-Law 48/2023), to be given to workers and to union representatives: building the shifts automatically and recording attendance both fall under it.
- An impact assessment (art. 35 of the GDPR): the Garante requires one for processing tied to the employment relationship carried out with technology from which remote monitoring could follow (decision no. 467 of 11 October 2018), all the more so where health data is involved.
- Limiting who in the venue can see the absences, and not using that data for decisions that have nothing to do with organizing the work.
On request we give you the technical information you need to write these documents: it's the assistance art. 28(3)(f) of the GDPR requires us to give you.
Why we handle the data, and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Answering people who write or call | Your name, the contact details you reach us from and what you write or say to us | Art. 6(1)(f) of the GDPR: our legitimate interest in following up the requests we receive and in building the commercial relationship. We are the controller. You can object at any time (art. 21) |
| Starting the free trial, managing the contract, the subscription and support, tickets included | Venue details, contact details, the owner's account, the text of the tickets | Art. 6(1)(b) of the GDPR: performance of the contract and pre-contractual measures taken at your request. We are the controller |
| Issuing the invoices, sending them to the Italian Exchange System and keeping the accounting records | The client's tax details, amounts, due dates | Art. 6(1)(c) of the GDPR: civil and tax obligations, in particular art. 2220 of the Italian Civil Code, arts. 21 and 39 of Presidential Decree 633/1972, Legislative Decree 127/2015 on e-invoicing, art. 22 of Presidential Decree 600/1973. We are the controller |
| Keeping the site and the infrastructure running: web server logs, fault diagnosis, defense against abuse and unauthorized access | IP address, date and time, page requested, outcome, referrer, browser type, account login data | Art. 6(1)(f) of the GDPR: our legitimate interest in keeping the service secure and working. We are the controller |
| Backups and security measures on the data inside the software | Your venue's staff data | Here we have no legal basis of our own: we handle it as a processor, on your instructions, to meet arts. 28 and 32 of the GDPR. You are the controller |
| Asserting or defending a right, for instance recovering an unpaid fee | Contract and subscription data, not staff data | Art. 6(1)(f) of the GDPR: our legitimate interest in protecting what we are owed. We are the controller |
| Organizing the shifts, recording attendance and absences, working out hours, costs and tips | All the staff data listed above | Here you are the controller. As a rule art. 6(1)(b) (the employment contract) and art. 6(1)(c) (the legal obligations on employment). We handle it only on your instructions, art. 28 of the GDPR |
| Recording absences for sickness and injury | Type of absence, dates and any notes | You are the controller: art. 9(2)(b) of the GDPR, read with art. 88 of the GDPR, with art. 2-septies of Legislative Decree 196/2003 and with art. 5 of Law 300/1970 |
What data you have to give us. What is needed to start and keep the account running and to issue the invoice — venue name, address, VAT number, a contact, the account email — you have to give us: without it we can't start or keep the service running, and we can't issue the tax documents the law requires of us. You can leave out, with no consequences, the landline number, the notes about the business and the certified email (PEC), if you would rather receive the e-invoice on a recipient code.
We don't ask for consent for these activities, because consent isn't the right basis: what we handle is there to make the software work for you, to invoice you or to comply with a law. And we don't do advertising or newsletters.
Who we pass the data to
We don't sell the data and we don't pass it to anyone for commercial purposes. We don't use it for advertising, ours or anyone else's. We don't put it into circulation to train automated systems. These are the recipients, by category:
| Who | What they do | In what capacity |
|---|---|---|
| OVH SAS | Hosts the server Muffin Staff runs on in the cloud and the one for the site you are reading, in France | Processor for the data we control, sub-processor for your staff data |
| Meta Platforms Ireland (WhatsApp) | Delivers the messages you choose to send us on WhatsApp | Independent controller for its own messaging service, with a notice of its own |
| Email and certified email (PEC) providers | Deliver and store the messages we exchange, and deliver the automatic emails the software sends to your employees | Processors for the data we control, sub-processors for your staff data |
| Stripe Payments Europe | Collects the subscription fee. It receives the data the payment needs; it doesn't receive your employees' data | Processor for the data we control, and independent controller for the anti-money-laundering duties that fall on it |
| The Italian Revenue Agency, the Exchange System, and any intermediary or archiving provider | Receive, transmit and store the e-invoices, which are compulsory under Legislative Decree 127/2015 | Independent controllers, by legal obligation |
| Lawyers and debt collection agents, only if the need arises | Protect a debt that has gone unpaid | Independent controllers or processors, depending on the engagement |
There are two lists, and it's worth not mixing them up. This table is the list of recipients of the data we control, and it's the one that governs. The sub-processors for your employees' data are listed instead in the art. 28 agreement you sign along with the contract, and every change is notified to you 30 days in advance.
Beyond these, we pass data on only if a law requires it of us or if a court or the police ask for it with a well-founded request. In that case, if we are allowed to, we tell you.
The software talks to the outside world in two cases, and these are they:
- It sends automatic emails to your employees: the initial password to whoever logs in for the first time, the shifts as soon as you publish them, a shift assigned or changed or taken away, and the outcome of an absence request or a shift swap. They leave from our mailbox and pass through our provider, which for these messages is a sub-processor. If the email doesn't go out the operation carries on anyway: the notice stays visible inside the software.
- It collects the fee through Stripe, if you have a subscription. Stripe receives the data the payment needs; it never sees your employees' data.
Apart from these two, there is no marketplace of integrations carrying your data elsewhere, and no calls to third-party services. The WhatsApp button on the Support page is a link, and it opens only if you press it.
If you use Muffin Staff installed on your own PC, none of this touches your employees' data: it never leaves your computer.
Where the data is
Muffin Staff in the cloud runs on a virtual server from OVH SAS, in a datacenter in France (the Gravelines and Dunkirk area, Hauts-de-France). The site you are reading is hosted by OVH too, in France: same supplier and same country, inside the European Union.
No data leaves the European Union. The only supplier that handles personal data on our behalf is OVH: staff records, shifts, clock-ins, absences, tips and tickets sit on that server, and the backup stays there. There is no transfer to a third country to declare to you under art. 13(1)(f) of the GDPR. With OVH the data processing agreement under art. 28 of the GDPR applies, the one OVH attaches to the contract and makes available to clients on request, which includes the standard contractual clauses of Implementing Decision (EU) 2021/914 for any transfers.
One clarification, so as not to claim more than is true: if you are the one who chooses WhatsApp to write to us, from the site, from your phone or from the button on the Support page, that message passes through the service of Meta Platforms Ireland, which is the independent controller of that service, with its own notice and its own safeguards. It happens only if you press that button, and from that moment its notice applies, not ours.
How long we keep the data
- Messages and contact requests, by email, WhatsApp or phone: if your request doesn't turn into a working relationship, we delete them within 24 months.
- Sign-ups made from the site and not yet confirmed: anyone who opens an account from muffin-staff.it/registrazione leaves us the venue's details and their own, but until they confirm, the venue doesn't exist: the request stays in a table of its own, it doesn't enter the client list and we don't use it for anything else. The confirmation link lasts 24 hours and the request is deleted within 7 days of that expiry. If the confirmation does arrive, the request stays 30 days — long enough to tell anyone who reopens the link that they have already used it — and is then deleted: from there on the venue's own periods apply, the ones above. The IP address of whoever fills in the form never enters the database: it is held in memory only, for an hour, to stop bots.
- Server logs: 90 days, then they are deleted. That covers both the web server logs and the software's own.
- Venue, contract and subscription data: for as long as the relationship lasts, and then under the 90-day rule below, subject to the tax retention periods.
- Staff data inside the software: for as long as the contract with us lasts. But you decide how long, because you are the controller: you can delete a person whenever you want.
- After the contract ends, or if a fee goes unpaid: access to the software closes, for you and for your employees. The data, though, stays stored for 90 days from the end: within that time you can ask us for a copy of your venue's data by writing to info@muffin-suite.com, and we send it to you. After the 90 days we delete it. The same applies if you only used the free trial and never subscribed. It's what art. 28(3)(g) of the GDPR requires: at the end of the service the data is either returned to you or deleted, whichever you choose.
- Backups: every night at 4:30 the server rebuilds the main archive, after checking it, and also keeps the last seven dated copies. Deleted data therefore disappears from the main archive on the first night after, and from the dated copies within seven days.
- Safety copy of deleted businesses: when an entire business is removed, before wiping it the software saves a file on the server with all of its data. It is there to put right a deletion made by mistake, and it goes into the nightly backup, and so into the seven dated copies as well. It is kept 90 days, then deleted.
- Activity log: 90 days, then it is deleted.
- Invoices and accounting records: 10 years, for the civil and tax obligations (art. 2220 of the Italian Civil Code). The period can run longer if an audit or a dispute is pending, because art. 22 of Presidential Decree 600/1973 requires keeping them until it is settled.
- Technical measurements on the server (processor, memory and disk usage): 30 days. Alerts: 365 days. They are numbers about the machine, they say nothing about you or your employees.
- Installed on your own PC: we keep nothing, because we have nothing.
What is left when you delete a person
It's worth being precise, because "deleted" doesn't always mean "gone for good". When you delete a person, their record, their clock-ins, their absences and their availability all disappear. What remains, with no record attached to it any more: their name in the tip splits already closed, their name in the support tickets they had opened, and the trace of the operation in the activity log, with name and email. They are there so that documents and conversations already closed don't become unreadable. The shifts they had been assigned don't disappear: they stay, but with no name, as uncovered shifts.
Remove an entire business instead, and all the staff records attached to it are deleted along with it, leaving the safety copy described above.
No automated decisions about people
This is the question an employee asks themselves when they find out that a program proposes the shifts, and the answer is better given before they ask it.
There are no decisions based solely on automated processing, the kind art. 22 of the GDPR restricts when they produce legal effects or significantly affect a person. The reason is a concrete one, not a formula: building the shifts produces a proposal, and the owner sees it, changes it and approves it before it becomes anything. The human step is real, not a rubber stamp: whoever approves can change any line, and the responsibility stays theirs. No shift, no assignment and no consequence for the employment relationship comes out of a calculation left to itself.
The software does work on data about people, though, in order to organize the work: it reads the rules you set yourself, that is holidays, days off, contract hours, availability, assignment priority, hour caps and preferred slot, and it produces statistics on hours worked and staff cost. That is automated processing, and we don't pretend otherwise. What it doesn't do is give people scores, ratings, classifications or judgments: nobody is rated for performance, for reliability or for behavior, and no ranking comes out of this processing.
The duty described above still stands: the notice to workers and to union representatives about automated systems, under art. 1-bis of Legislative Decree 152/1997, has to be given even when there are no decisions within the meaning of art. 22.
How we protect the data
They are technical measures, but they can be put in plain words:
- Passwords are not stored in the clear. We keep only a fingerprint computed with scrypt and a salt, and the comparison runs in constant time, so the password can't be guessed by measuring how long the server takes to answer. There are minimum strength requirements. The initial password, when we are the ones who generate it, is random and has to be changed on first login; anyone who opens the account themselves from the site chooses their own, and it stays that one until they decide to change it.
- If you change the password, every open session drops. Sessions are signed and tied to the password fingerprint: change it, and anyone who had logged in with the old one is thrown out.
- The "Log out" button really logs you out. There is a revocation counter for every user: logging out also invalidates any cookies copied onto another device, not just the one in the browser you are using.
- The clock-in QR code is signed and lasts 30 seconds. It can't be photographed to clock in from home the next day.
- In the cloud you browse over HTTPS only, and the software's cookies are all technical: they are HttpOnly, so the page scripts can't read them, and they travel only over an encrypted connection. The name, purpose, lifetime and attributes of each one are on the cookies page: that's where you find them listed one by one. Among them are the single-use cookies that show a freshly generated password once: that password travels there because you have to be able to read it once; only the encrypted fingerprint stays in the database, never the password in the clear.
- Venues are isolated, both in the way the software queries the database and in the rules of the database itself, which delete the data attached to a removed company along with it.
- The site has a strict Content-Security-Policy: fonts, stylesheets and page scripts can only come from our own domain, plus the images embedded in the page itself. There are no authorized external destinations: the only address allowed besides the site is api.muffin-suite.com, which is ours and isn't in use today.
- Nightly maintenance at 4:30: a scheduled job on the server clears things out, runs the backup and checks it, then restarts the machine. The interruption lasts a few tens of seconds. If the backup fails, the restart isn't done and the previous night's copy stays untouched.
- Where the backup sits: on the same machine as the software, in France, readable only by the administrator; next to the main archive are the last seven dated copies. It isn't sent to any outside service. That cuts down the points of exposure, but the other side has to be said too: lose the machine and you lose the backup with it, and anyone who got that access would have everything. It's the reason access to the server is restricted.
- Access to the server: there is a single administrative account on the machine, and it belongs to Antonio Fuccillo. Nobody else has the credentials. Beyond him, physical access to the machines belongs to OVH, as with any hosting provider.
- The software doesn't call outside services: fewer roads out, fewer ways to lose data.
If a breach happens
No measure makes a system invulnerable, and we won't promise you otherwise. If a personal data breach were to happen, there are two scenarios and they shouldn't be mixed up:
- Where we are the processor, that is for the data inside the software: we tell you without undue delay, as art. 33(2) of the GDPR requires, with what we know. Deciding whether to notify the Garante is up to you, as the controller, and we give you the information to decide.
- Where we are the controller, that is for the site, the contacts, the contract, the subscription, the invoicing and the accounts: we notify the Garante ourselves within 72 hours, as art. 33(1) requires, and if the breach carries a high risk to your rights we tell you directly, as art. 34 requires.
Your rights
The GDPR gives you rights, and you exercise them by writing to us, with no special wording:
- Access (art. 15): knowing what data there is and asking for a copy
- Rectification (art. 16): correcting what is wrong or incomplete
- Erasure (art. 17): having it deleted, when no obligation requires us to keep it, such as the tax rules on invoices
- Restriction (art. 18): asking for it to be held still while a dispute is cleared up
- Portability (art. 20): getting back in a readable format the data you gave us, to take it elsewhere. It applies only to data we handle by automated means on the basis of the contract or of a pre-contractual request of yours: it doesn't extend to the invoices and the accounting records, which we keep by legal obligation, nor to data we handle on legitimate interest
- Automated decisions (art. 22): here you have nothing to ask for, because we don't make any
Your right to object
We write this one out separately, because art. 21(4) of the GDPR requires that it be brought to your attention explicitly and apart from the rest.
You have the right to object at any time to the handling of your data based on our legitimate interest (art. 6(1)(f)): in our case that means answering people who write to us, keeping the infrastructure secure and protecting a debt. Writing to us at info@muffin-suite.com is enough, with no need to give reasons. If you object we stop, unless we show compelling legitimate grounds that override your interests, or the processing is needed to establish or defend a legal claim. We don't do direct marketing; if one day we did, the objection would be absolute and without exception.
Write to info@muffin-suite.com. We answer within one month, as art. 12(3) of the GDPR provides; if the request is a complicated one we can take longer, but we tell you first.
If you work in a venue that uses Muffin Staff
If you are an employee and you want to see, correct or delete your data, the request goes to your employer, not to us: your employer is the controller, and the decisions about that data are theirs. The notice about how your data is handled has to come from them too: this page is no substitute for it. It isn't us passing you around, it's how art. 28 of the GDPR works.
That said, we leave nobody stranded. If you write to us, we pass the request on to the owner of your venue and help them answer you: pulling the data out, correcting it, deleting it. We do the technical part, the decision stays theirs.
Complaint to the Garante
If you think your data is being handled badly, you can lodge a complaint with the Garante per la protezione dei dati personali: forms and instructions are on garanteprivacy.it. It's a right you always have (art. 77 of the GDPR), even without having written to us first. Or you can take it to the ordinary courts.
If this notice changes
If we change something substantial, a new recipient of the data for instance, or a different purpose, we update this page and change the date below. If you are a client and the change really concerns you, we write to you by email: it isn't on you to check the site every month to find out.
If you need an earlier version of this page, ask us for it at info@muffin-suite.com: we keep them.
Last updated: July 30, 2026